Dec 12

How to avoid the certificate error with Cisco’s WLC internal Web Authentication

Have you ever visited a business and you were given a username and password for their guest wireless access, only to get an SSL Certificate error when it sends you to the authentication page? Is it safe or not?

On the Cisco wireless controller there is a layer 3 security feature called Web-Auth. When the authentication is set to Web-Auth the user attaches to an SSID, then when they open their web browser it forces them to a login screen. The user then has to enter a username and password. After authenticating the user is allowed to use the wireless network.

The default settings on the controller is to force the user to https://1.1.1.1 (1.1.1.1 would be the virtual address on the controller). When this happens, the controller uses a self signed certificate and there for it gives the end users a certificate error.


I recently tried to import a public certificate to my Cisco 5508 controller (Version 7.6.130.0) to avoid this error. After working with my coworker that manages the certificates, along with Cisco TAC, I found this to be a very difficult task. Every time I tried to import the certificate file it errored out. Later I found out from TAC that version 7.6 had a bug that didn’t allow a certificate to be imported. I was forced to downgrade to 7.4 to load the certificate. I did the downgrade, I didn’t lose my config as I expected. I imported the certificate on version 7.4. My APs are 3702s so they are not supported in version 7.4, I had to upgrade to 7.6 in order to test the certificate. After upgrading, I still got the error. We tried it again and it failed again. Each time we modified the certificate, downgrade, then upgrade. This process took a long time only to have it fail. I’m not sure what was wrong, but with our certificate guy and Cisco TAC, we couldn’t get it to work. The certificate error continued. We did indeed have an address on the virtual interface with a DNS Host name and the address was in DNS.

After some more research I found that I could change that authentication page from https to http. On the controller go to MANAGEMENT –> HTTP-HTTPS. The third item from the top is “WebAuth SecureWeb”, the options are enable or disable. Mine was set to enable so I changed it to disable. You then need to go to CONTROLLER –> INTERFACES –> VIRTUAL make sure the “DNS Hostname” field is empty. The IP address does not matter, 1.1.1.1 is very common. If you change the virtual address you will need to reboot the controller.

After changing the WebAuth SecureWeb to disable and rebooting the controller your guests can access and enjoy an authentication screen without the SSL certificate error.

Does it matter that it’s not secure? For a guest that is getting a random or shared username/password, I don’t think so. What do you think?

Sep 13

How many clients can a Cisco 3702 AP service before service degrades?

I understand that the proper answer to this question is “It depends”. But, my goal is to find the number of simultaneous wireless telephone calls that can be made while attached to the same Cisco 3702 series access point (AP) and same radio A or B/G? I’m not looking for a book answer, I have already found the Cisco Unified Wireless IP Phone 7925G Deployment Guide. On Page 42 is states 13 calls at 6 Mbps, 20 calls at 12 Mbps, and 27 calls at 24-54 Mbps.


So what is the reality of the 3702 series AP? That’s my question. Using a Cisco 7921/7925 IP phone, How many calls have you had going on your network before people started complaining?

On a Cisco 1252 AP, I found that once I hit 14-20 clients running terminal emulation software, the performance was very poor. The clients were using Telnet and it took a long time for the users to login and get their first assignment.

What about running a telephone application like the Shortel client. This client is loaded on a smartphone and makes calls over the WiFi. Have any of you used this client on a Cisco Wireless network? If so, what APs and controllers did you use? How was your experience?

Placing my configuration aside, can you give me good feedback about your experience with these products?